logo

Palo Alto Networks zero-day exploited since March to backdoor firewalls

ID: 6ff1d84b-a8bc-5d96-8f67-c874397cb437

STIX ID: report--6ff1d84b-a8bc-5d96-8f67-c874397cb437

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-04-13

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Suspected state-sponsored actors (tracked by Volexity as UTA0218) have been exploiting a PAN-OS GlobalProtect zero-day (CVE-2024-3400) since late March to install a Python backdoor called 'Upstyle', execute commands via log-parsing, deploy additional tools (reverse shells, GOST) and exfiltrate sensitive artifacts including Active Directory databases and browser credential stores; Palo Alto disclosed mitigations and scheduled patches after being notified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.